PSIRT Advisories

The following is a list of advisories for issues resolved in Fortinet products. The resolution of such issues is coordinated by the Fortinet Product Security Incident Response Team (PSIRT), a dedicated, global team that manages the receipt, investigation, and public reporting of information about security vulnerabilities and issues related to Fortinet products and services.  

For details of how to raise a PSIRT Issue with Fortinet, please see our PSIRT Policy here.

Certificates taken out of service could potentially be improperly re-used. Impact detailFortinet has already taken steps to mitigate...

Jul 19, 2019 Risk IR Number: FG-IR-19-144
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") in FortiNAC admin webUI may allow an unauthenticated...

Jul 16, 2019 Risk IR Number: FG-IR-19-140
The URL part of the report message is not encoded in Fortinet FortiWeb which may allow an attacker to execute unauthorized code...

Jun 12, 2019 Risk IR Number: FG-IR-19-070
Server Message Block (SMB) 1.0 - a legacy file and print sharing protocol - has been deprecated by Microsoft due to multiple weaknesses...

Jun 04, 2019 Risk IR Number: FG-IR-17-103
Failure to sanitize the login redir parameter in the SSL-VPN web portal may allow an attacker to perform a Cross-site Scripting...

May 24, 2019 Risk IR Number: FG-IR-17-242
Failure to properly parse message payloads in the SSL VPN portal of FortiOS may allow a non-authenticated attacker to perform...

May 17, 2019 Risk IR Number: FG-IR-18-387
Failure to sanitize input in the customized data pattern webpage of FortiCASB  may allow an authenticated attacker to conduct...

May 15, 2019 Risk IR Number: FG-IR-19-001
The Missing Encryption Of Sensitive Data vulnerability in FortiClient may allow an attacker to access VPN session cookie from...

Apr 23, 2019 Risk IR Number: FG-IR-19-110
A cleartext transmission of sensitive information vulnerability in FortiManager may allow an unauthenticated attacker in a man...

Apr 23, 2019 Risk IR Number: FG-IR-18-051
Some FortiAP models are vulnerable to the Bleeding Bit Vulnerability (CVE-2018-16986) present in the Texas Instruments WiFi chips.CVE-2018-16986:Texas...

Apr 10, 2019 Risk IR Number: FG-IR-18-356
FortiSwitch is vulnerable to multiple Cross-site Scripting (XSS) attacks present in the jQuery javascript libraryCVE-2015-9251:jQuery...

Apr 10, 2019 Risk IR Number: FG-IR-18-013
An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing settings...

Apr 04, 2019 Risk IR Number: FG-IR-18-230
A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox may allow an attacker to execute unauthorized code...

Apr 03, 2019 Risk IR Number: FG-IR-18-024
An improper access control vulnerability in FortiClientMac may allow an attacker to affect the application's performance via modifying...

Apr 02, 2019 Risk IR Number: FG-IR-19-003
An information exposure vulnerability in the admin portal of FortiSIEM may allow an authenticated admin to retrieve the LDAP server...

Mar 29, 2019 Risk IR Number: FG-IR-18-382